Mimecast³ÆSolarWindsºÚ¿ÍÒÑÇÔÈ¡Æä²¿ÃÅÔ´´úÂ룻ÎÖ´ï·áÎ÷°àÑÀ·Ö¹«Ë¾Î¥·´GDPR±»· £¿î½üǧÍòÃÀÔª

°ä²¼¹¦·ò 2021-03-18

1.Mimecast³ÆSolarWindsºÚ¿ÍÒÑÇÔÈ¡Æä²¿ÃÅÔ´´úÂë


1.jpg


µç×ÓÓʼþ°²È«¹«Ë¾Mimecast³ÆSolarWinds±³ºóµÄºÚ¿ÍÒÑÇÔÈ¡Æä²¿ÃÅÔ´´úÂë¡£ÔçÔÚ2020Äê1Ô£¬Mimecast·¢ÏÔìäÔâµ½¹¥»÷µ¼ÖÂMicrosoft 365 SSLÖ¤Êéй¶£¬Ó°ÏìÁËÔ¼10%µÄÓû§¡£3ÔÂ16ÈÕ£¬¸Ã¹«Ë¾°ä²¼ÉêÃ÷³ÆºÚ¿Í»¹ÇÔÈ¡ÁËÓʼþµØÖ·ºÍƾ֤µÈÐÅÏ¢£¬ÒÔ¼°²¿ÃÅÔ´´úÂë¡£µ«ÊǺڿͲ¢Î´¶ÔÔ´´úÂë½øÐÐÈκÎÅú¸Ä£¬²¢ÇÒÓÉÓÚÆäÇÔÈ¡µÄÔ´´úÂë²»ÆëÈ«£¬¿ÉÄÜÎÞ·¨¿ª·¢³öMimecast·þÎñµÄÈκÎ×é¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mimecast-solarwinds-hackers-stole-some-of-our-source-code/


2.Descartes AljexÒòAWS S3ÅäÖÃÃýÎóй¶103GBÊý¾Ý


2.jpg


Website Planet·¢ÏÖÔËÊäÖÎÀíÈí¼þDescartes AljexÒòAWS S3´æ´¢Í°ÅäÖÃÃýÎóй¶ÁË103 GBÊý¾Ý¡£Õâ´ÎÊÂÎñÓ°ÏìÁ˸ù«Ë¾µÄ¿Í»§¡¢Ô±¹¤¡¢ÏúÊÛ´ú±íÒÔ¼°ÎªµÚÈý·½Ô±¹¤£¬Ð¹Â¶ÁËÐÕÃû¡¢µç»°ºÅÂ룬µç×ÓÓʼþµØÖ·£¬AljexÓû§ÃûºÍ´¿Îı¾ÃÜÂëµÈÓ×ÎÒÐÅÏ¢£¬ºÍÊÕ¼þÈËÐÕÃû¡¢»õ¼þÆðÔ˵غÍÖ÷Õŵء¢µØÖ·ºÍµç»°ºÅÂëµÈ»õ¼þÐÅÏ¢¡£Website PlanetÓÚ2020Äê12ÔÂ24ÈÕ·¢ÏÖ¸ÃÎÊÌ⣬Ŀǰ¸Ã´æ´¢Í°ÒѾ­±»±£»¤ÆðÀ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/shipping-management-software-firm-data-online/


3.Sucuri·¢ÏÖÀûÓÃJPG°µ²ØÐÅÓþ¿¨Êý¾ÝµÄMagecart¹¥»÷»î¶¯


3.jpg


ÍøÕ¾°²È«¹«Ë¾SucuriµÄ×êÑÐÈËÔ±ÔÚ¶ÔÊÜϰȾµÄMagento 2µç×ÓÉÌÎñÍøÕ¾½øÐе÷²éʱ£¬·¢ÏÖMagecart¹¥»÷ÕßÀûÓÃJPG°µ²ØÐÅÓþ¿¨Êý¾Ý¡£Magecart¹¥»÷ʼÓÚ¼¸Äêǰ£¬ºÚ¿ÍÀûÓöñÒâ´úÂëÔÚÓû§½áÕÊʱÇÔÈ¡ÆäÐÅÓþ¿¨Êý¾Ý¡£ÔÚÕâ´ÎµÄ·¢ÏֵĹ¥»÷»î¶¯ÖУ¬ºÚ¿Í²¢Ã»Óе±¼´½«Êý¾Ý·¢Ë͵½ËûÃǵķþÎñÆ÷£¬¶øÊǽ«Æä°µ²ØÔÚÊÜϰȾµÄÍøÕ¾µÄJPGͼÏñÖУ¬´Ó¶øÏ÷¼õ¿ÉÒÉÁ÷Á¿£¬ÒÔÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115655/hacking/magecart-credit-card-jpg.html


4.°ÍÈûÂÞÄÇÒÉËÆÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÊÐÕþϵͳ̱»¾


4.jpg


°ÍÈûÂÞÄÇ£¨AMB£©ÒÉËÆÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ÆäÊý×Ö·þÎñ±»ÆÈÔÝÍ£¡£¸ÃÊÐÓÚ3ÔÂ10ÈÕ¼ì²âµ½Õâ´Î¹¥»÷£¬ÎªÁËÔ¤·À¶ñÒâÈí¼þµÄ´«²¼£¬¸ÃÊÐÖжÏÁËÊÐÕþϵͳ£¬Ô̺¬µç»°·þÎñ¡¢ÆäËûÊý×Ö·þÎñºÍÍøÕ¾¡£AMB½²»°È˰µÊ¾£¬Õâ´Î¹¥»÷»î¶¯ÓëSEPEÉÏÖÜÔâÓöµÄ¹¥»÷ÓÐËù·ÖÆç£¬µ«¼«¶ÈÀàËÆ¡£Ä¿Ç°£¬¸ÃÊÂÎñÈÔÔÚµ÷²éÖС£


Ô­ÎÄÁ´½Ó£º

https://www.muyseguridad.net/2021/03/16/area-metropolitana-de-barcelona/amp/


5.ÎÖ´ï·áÎ÷°àÑÀ·Ö¹«Ë¾Î¥·´GDPR±»· £¿î½üǧÍòÃÀÔª


5.jpg


µçÐŹ«Ë¾ÎÖ´ï·áÎ÷°àÑÀ·Ö¹«Ë¾ÒòÎ¥·´GDPR±»· £¿î½üǧÍòÃÀÔª¡£¸Ã¹«Ë¾ÒòʹÓò»Êʵ±µÄµç»°ÏúÊÛÕ½ÊõÒÔ¼°Î´Äܱ£»¤Êý¾Ý¶øµ¼ÖÂÁË4Ïî· £¿î£¬¹²¼Æ972ÍòÃÀÔª¡£ ǰÁ½Ïî· £¿îÓ롶ͨÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©ÓйØ£¬×ܼÆ716ÍòÃÀÔª¡£µÚÈýÏî· £¿îÓëÎ÷°àÑÀÊý×Ö°æÈ¨ºÍµçÐŵÄ˾·¨ÒÔ¼°GDPRÓйØ£¬Îª239ÍòÃÀÔª¡£µÚËÄÏî· £¿îÉæ¼°Î÷°àÑÀCookieµÄ˾·¨£¬Îª17.9ÍòÃÀÔª¡£´Ó2018Äê1Ôµ½2020Äê2Ô£¬ÎÖ´ï·áÎ÷°àÑÀ·Ö¹«Ë¾Òѱ»ÖÒ¸æ»ò· £¿î50ÂŴΡ£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/aepd-issues-highest-ever-fine/


6.CISAºÍFBI½áºÏ°ä²¼¹ØÓÚTrickBot¶ñÒâÈí¼þµÄ°²È«Õ÷ѯ


6.jpg


CISAºÍÁª¹úµ÷²é¾Ö£¨FBI£©°ä²¼ÁËÓйØTrickBot¶ñÒâÈí¼þµÄ½áºÏÍøÂ簲ȫÕ÷ѯ£¨CSA£©¡£¸ÃÕ÷ѯ½éÉÜÁËTrickBotµÄ¼¼Êõϸ½Ú¡¢MITRE ATT&CK Techniques¡¢¿úËÅÊý¾ÝÒÔ¼°»º½â´ëÊ©¡£TrickBotÊÇÒ»Öָ߼¶Ä¾Âí£¬Í¨¹ýÓã²æÊ½´¹µö»î¶¯£¬Ê¹ÓÃÔ̺¬¶ñÒ⸽¼þ»òÁ´½ÓµÄÌØÔìµç×ÓÓʼþÀ´´«²¼¡£¸Ã°²È«Õ÷ѯ½¨Òé×éÖ¯×èÖ¹¿ÉÒɵÄInternetºÍ̸µØÖ·¡¢Ê¹ÓÃɱ¶¾Èí¼þÒÔ¼°ÎªÔ±¹¤ÌṩÉç»á¹¤³ÌºÍÍøÂç´¹µöÅàѵµÈ·½Ê½À´·À±¸´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/03/17/cisa-fbi-joint-advisory-trickbot-malware-0